CVE Tools

Elecom

47 CVEs tracked since 2021. Since Feb 2021, none of them reached CISA KEV.

Elecom CVEs per month

Feb 2021 to Aug 2024. Point at a month, or focus the strip and use the arrow keys.
Elecom CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0290
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-0720
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12130
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-0790
2023-08100
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-0840

Products

The products that kept showing up in Elecom's monthly top three, with their CVEs summed over those months.

  1. Edwrc-2533gst2 Firmware61 month
  2. Wrc-1167gst2 Firmware61 month
  3. Wrc-1167gst2a Firmware61 month
  4. Wrc-1167ghbk3-a Firmware51 month
  5. Wrc-1167febk-a Firmware41 month
  6. Wrc-1167ghbk-s Firmware41 month
  7. Wrc-300febk-s Firmware31 month
  8. Wab-i1750-ps Firmware21 month
  9. Wrc-1467ghbk-a Firmware21 month
  10. Wrc-1467ghbk-s Firmware21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Elecom.

  1. CVE-2026-24465Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.9.8
  2. CVE-2026-22550OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.8.8
  3. CVE-2024-43689Stack-based buffer overflow vulnerability exists in ELECOM wireless access points. By processing a specially crafted HTTP request, arbitrary code may be executed.9.8
  4. CVE-2024-39300Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login to the product withou...3.7
  5. CVE-2024-34577Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malic...6.1
  6. CVE-2024-42412Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in menu.cgi. If a user views a malicious web page while logged in to the produc...6.1
  7. CVE-2024-40883Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be d...8.8
  8. CVE-2024-23910Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and ...8.8
  9. CVE-2024-21798ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another ad...4.8
  10. CVE-2024-22372OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted...6.8
  11. CVE-2023-49695OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege ...6.8
  12. CVE-2023-43752OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000GS2A-B v1.05 and earlier allows a network-adjacent authenticated user to execu...8.0
  13. CVE-2023-43757Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key u...6.5
  14. CVE-2023-40072OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request.8.8
  15. CVE-2023-40069OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected p...9.8

The record

Peak rank
#42 in Dec 2021
Busiest month shown
Dec 2021, 13 CVEs
Months with a KEV entry
0 since Feb 2021
Monthly snapshots
6 since 2021
Elecom's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store